Platform — Lucy Frontline
Security, data protection and compliance.
We publish what we have, and name what we don't. No forms, and no gaps left for you to discover on a call.
01 / 04
Information security
- Infrastructure
The application tier runs in Frankfurt (DigitalOcean App Platform) and the data platform in Ireland (Supabase, eu-west-1). Traffic is encrypted in transit (HTTPS/WSS) and the managed data platform encrypts data at rest. Application containers are ephemeral and persist no customer data.
- Access and authentication
Production administration is limited to two named engineers, with MFA enforced across the infrastructure organisations. Tenant isolation combines server-side logic, database Row Level Security, private storage policies and automated tests verifying that one tenant is denied access to another's data.
- Backup and recovery
The production database has point-in-time recovery with a seven-day window. An important limitation is disclosed under “What we don't publish yet”.
- Incident handling
Affected customers are notified as soon as reasonably possible after material impact is identified, subject to stricter contractual or legal requirements.
Documents
- ↓Technical and organisational measures
02 / 04
AI and worker data
Lucy Frontline's AI features are bounded tools — task analysis, import extraction, avatars and translation. They do not evaluate employee work performance, never grant permissions and make no decisions about employees.
Employee-import output is always human-reviewed, and the prompt contract prohibits invented contact details, roles and permissions. Execution logs record provider, model, feature and outcome — never raw prompt content or raw model responses.
Today's provider endpoints (OpenAI, Google Translation) are global — we do not claim EU-only processing. OpenAI does not use API data for training by default; abuse monitoring may retain content up to 30 days. EU endpoints are planned, as is an open-model option on Swedish infrastructure for customers with such requirements. Providers may change within the contracted processing region; changing the contracted region requires your agreement.
Documents
- ↓Technical documentation — AI-assisted features
03 / 04
Sub-processors
Lucy Frontline's sub-processors: Supabase (data platform, Ireland) · DigitalOcean (application hosting, Frankfurt) · OpenAI (AI features, global endpoint) · Google Cloud (translation) · Sentry (error monitoring, ingested in Germany) · 46elks (SMS, Sweden) · Resend (email — note the provider stores account data and metadata in the US). A DPA is available; the sub-processor schedule is being updated for Lucy Frontline and is provided on request.
Documents
- ↓Sub-processor list
04 / 04
What we don't publish yet
We do not publish the following today, because it is not done — and a reviewer should hear it from us first
Files in object storage are not covered by database point-in-time recovery — a deleted file cannot be restored. Separate file backup is work in progress.
Independent certification · External penetration test · Contractual availability level (SLA) · Completed disaster-recovery exercise (runbook in progress) · Updated sub-processor schedule (in progress)
For your review team
A dated security and privacy pack — hosting details, backup evidence, administrator list, AI provider inventory, DPA and sub-processor register — is provided on request during evaluation. All platform pages are open: no email gate, no forms.
contact@lucyanalytics.com
This page is supporting material and process knowledge, not legal advice. Your own counsel is responsible for the assessment in each individual case.
Last verified: 2026-08-11. This page is updated when the facts change — not the other way around.
